Hier ist das ESET log: Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=c59d34d9170f4b449a0ee9140efcc4ed
# engine=14101
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-18 06:36:27
# local_time=2013-06-18 08:36:27 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 91 372426 148290459 0 0
# compatibility_mode=5893 16776574 100 94 20395097 123210437 0 0
# scanned=523562
# found=0
# cleaned=0
# scan_time=18647 Code:
OTL logfile created on: 18.06.2013 23:06:28 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\xXBaseXx\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,99 Gb Total Physical Memory | 4,37 Gb Available Physical Memory | 54,72% Memory free
15,98 Gb Paging File | 12,17 Gb Available in Paging File | 76,15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 323,25 Gb Free Space | 34,71% Space Free | Partition Type: NTFS
kl
Computer Name: XXBASEXX-PC | User Name: xXBaseXx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013.06.17 17:43:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xXBaseXx\Desktop\OTL.exe
PRC - [2013.06.14 13:12:34 | 001,855,880 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
PRC - [2013.05.30 18:58:58 | 000,144,384 | ---- | M] (Adobe Systems Inc.) -- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.30\deploy\LolClient.exe
PRC - [2013.05.22 21:11:31 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.05.09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2013.04.25 00:10:06 | 000,659,224 | ---- | M] (Logitech Inc.) -- C:\Programme\Logitech Gaming Software\Applets\LCDMedia.exe
PRC - [2013.04.01 01:44:47 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013.03.01 15:15:46 | 002,693,448 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.164\deploy\LoLLauncher.exe
PRC - [2013.03.01 15:13:08 | 001,300,816 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
PRC - [2012.07.24 05:46:36 | 000,164,168 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
PRC - [2012.07.24 05:46:34 | 000,405,832 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
PRC - [2010.12.18 18:56:48 | 000,095,272 | ---- | M] (EnTech Taiwan) -- C:\Windows\SysWOW64\softLCP.exe
PRC - [2010.12.18 18:56:34 | 000,291,384 | ---- | M] (EnTech Taiwan) -- C:\Program Files (x86)\softOSD\softOSD.exe
PRC - [2010.11.20 14:17:56 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
PRC - [2009.02.23 12:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
========== Modules (No Company Name) ==========
MOD - [2013.06.14 13:12:34 | 016,033,160 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
MOD - [2013.05.22 21:11:30 | 003,128,728 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013.03.01 15:15:46 | 002,693,448 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.164\deploy\LoLLauncher.exe
MOD - [2013.03.01 15:13:08 | 001,300,816 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
MOD - [2012.07.24 05:46:36 | 000,164,168 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
MOD - [2012.07.24 05:46:34 | 000,405,832 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
MOD - [2012.07.21 08:44:58 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
MOD - [2012.07.21 08:44:54 | 000,335,872 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
MOD - [2012.07.21 08:44:38 | 000,225,280 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
MOD - [2012.07.21 08:44:30 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
MOD - [2012.07.21 08:44:22 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
MOD - [2012.06.04 18:23:18 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSSHooks.dll
MOD - [2012.06.04 17:03:40 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTMUI.dll
MOD - [2012.06.04 17:02:42 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTUI.dll
MOD - [2012.06.04 17:02:34 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTFC.dll
MOD - [2011.04.30 17:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
MOD - [2011.04.30 17:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTTSH.dll
MOD - [2009.08.26 06:29:28 | 000,150,016 | ---- | M] () -- C:\Windows\SysWOW64\OemSpiE.dll
MOD - [2009.03.26 15:46:42 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009.02.06 19:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
========== Services (SafeList) ==========
SRV:64bit: - [2013.02.26 20:24:44 | 000,240,640 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.06.14 13:12:34 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.06.07 00:06:24 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.05.22 21:11:31 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013.04.01 01:44:47 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012.08.10 12:42:54 | 000,150,464 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2012.07.13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012.06.10 02:14:06 | 000,263,808 | ---- | M] (Josip Medved) [Disabled | Stopped] -- C:\Programme\Josip Medved\VHD Attach\VhdAttachService.exe -- (VhdAttach)
SRV - [2012.01.24 13:50:46 | 000,168,864 | ---- | M] () [Disabled | Stopped] -- C:\Programme\Common Files\WireHelpSvc.exe -- (WireHelpSvc)
SRV - [2011.12.08 18:21:47 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe -- (Creative Media Toolbox 6 Licensing Service)
SRV - [2011.12.08 18:17:48 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2011.09.07 16:29:20 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2011.04.24 23:08:00 | 004,303,928 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2011.02.28 10:16:38 | 000,011,776 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Dell\PowerNap\PowerNap.Service.exe -- (dell_power_nap_service)
SRV - [2011.01.10 14:49:20 | 000,014,848 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe -- (DokanMounter)
SRV - [2010.12.18 18:56:34 | 000,291,384 | ---- | M] (EnTech Taiwan) [Auto | Running] -- C:\Program Files (x86)\softOSD\softOSD.exe -- (softOSD)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.08.18 13:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.23 12:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013.05.09 10:59:07 | 001,025,808 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2013.05.09 10:59:07 | 000,378,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2013.05.09 10:59:07 | 000,189,936 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2013.05.09 10:59:07 | 000,072,016 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2013.05.09 10:59:07 | 000,065,336 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013.05.09 10:59:07 | 000,064,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2013.05.09 10:59:06 | 000,080,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2013.05.09 10:59:06 | 000,033,400 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2013.02.26 21:17:50 | 011,613,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.02.26 19:58:04 | 000,576,000 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.02.12 23:01:36 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss6.sys -- (taphss6)
DRV:64bit: - [2013.01.17 21:15:12 | 000,066,800 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGSHidFilt.Sys -- (LGSHidFilt)
DRV:64bit: - [2013.01.15 12:11:26 | 000,096,768 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.08.23 16:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 16:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.24 14:50:38 | 000,025,528 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ESLvnic.sys -- (ESLvnic1)
DRV:64bit: - [2012.01.24 13:50:38 | 000,147,472 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\ESLWireACD.sys -- (ESLWireAC)
DRV:64bit: - [2011.07.26 19:49:12 | 000,037,888 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011.01.15 18:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2011.01.10 14:51:40 | 000,120,408 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\dokan.sys -- (Dokan)
DRV:64bit: - [2010.12.17 00:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010.11.20 15:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010.11.20 15:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010.11.20 13:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010.05.28 13:04:52 | 000,017,456 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2010.03.04 13:43:00 | 000,346,144 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010.02.15 23:21:32 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2010.02.15 23:21:31 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2009.11.24 02:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009.11.24 02:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009.11.18 08:12:00 | 000,032,344 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MBfilt64.sys -- (MBfilt)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.17 09:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009.06.17 09:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009.06.17 09:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.06 03:34:52 | 000,639,512 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\t3.sys -- (t3)
DRV:64bit: - [2009.02.03 17:46:14 | 000,077,952 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfsync04.sys -- (sfsync04)
DRV:64bit: - [2009.02.03 17:37:50 | 000,075,384 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfdrv01.sys -- (sfdrv01)
DRV:64bit: - [2007.06.25 10:42:22 | 000,108,072 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s117bus.sys -- (s117bus)
DRV:64bit: - [2007.05.03 18:19:38 | 000,014,032 | ---- | M] (EnTech Taiwan) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\se64a.sys -- (se64a)
DRV:64bit: - [2006.09.30 11:36:14 | 000,013,008 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pstrip64.sys -- (PStrip64)
DRV:64bit: - [2006.06.14 16:58:10 | 000,014,192 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sfhlp02.sys -- (sfhlp02)
DRV - [2012.07.24 05:46:34 | 000,010,568 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2010.10.22 10:37:36 | 000,014,136 | ---- | M] (MSI) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys -- (NTIOLib_1_0_4)
DRV - [2010.05.10 10:44:40 | 000,033,592 | ---- | M] (Your Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys -- (MSI_MSIBIOS_010507)
DRV - [2010.01.29 11:40:16 | 000,115,600 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive)
DRV - [2009.12.31 14:00:46 | 000,019,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys -- (RivaTuner64)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2007.05.03 18:19:38 | 000,014,032 | ---- | M] (EnTech Taiwan) [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\se64a.sys -- (se64a)
DRV - [2004.12.30 23:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
DRV - [2004.05.13 15:00:04 | 000,111,808 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.05.13 13:19:36 | 000,079,488 | ---- | M] (Protection Technology) [Kernel | System | Stopped] -- C:\Windows\SysWOW64\drivers\prodrv06.sys -- (prodrv06)
DRV - [2003.12.01 17:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.09.06 14:22:08 | 000,006,944 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\prosync1.sys -- (prosync1)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.msn.com/?ocid=EIE9HP&PC=UP50
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.msn.com/?ocid=EIE9HP&PC=UP50
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9C C2 45 B4 AA D0 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: npretoxlive%40live.heroesandgenerals.com:1.0.3.5
FF - prefs.js..extensions.enabledAddons: client%40anonymox.net:1.0.2
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130515
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.6.2
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.8
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: Strata40@SpewBoy.au:0.6.2
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 5555
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar: C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\Sonar\npesnsonar.dll (ESN AB)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.3: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.3\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch: C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\npesnlaunch.dll (ESN AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.104.0: C:\Program Files (x86)\Battlelog Web Plugins\1.104.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.116.0: C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.138.0: C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.96.0: C:\Program Files (x86)\Battlelog Web Plugins\1.96.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.3: C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@live.heroesandgenerals.com/npretox: C:\Program Files (x86)\Heroes & Generals\live\npretoxlive.dll (Reto-Moto ApS)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.12.30 06:25:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.06.14 00:24:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.22 21:09:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.22 21:09:41 | 000,000,000 | ---D | M]
[2009.12.31 02:00:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Extensions
[2013.05.31 20:11:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions
[2013.05.17 07:42:10 | 000,000,000 | ---D | M] (WOT) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011.03.15 14:19:35 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions\battlefieldplay4free@ea.com
[2013.04.06 14:11:20 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions\ich@maltegoetz.de
[2012.07.27 22:38:34 | 000,000,000 | ---D | M] (HNG downloader/starter (live)) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions\npretoxlive@live.heroesandgenerals.com
[2010.04.21 20:38:39 | 000,000,000 | ---D | M] ("Strata40") -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions\Strata40@SpewBoy.au
[2010.04.21 20:38:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\Firefox\Profiles\kp8852w0.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\extensions
[2013.05.07 20:07:51 | 000,363,920 | ---- | M] () (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\firefox\profiles\kp8852w0.default\extensions\client@anonymox.net.xpi
[2013.05.31 20:11:34 | 000,699,920 | ---- | M] () (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\firefox\profiles\kp8852w0.default\extensions\jid1-qQSMEVsYTOjgYA@jetpack.xpi
[2013.05.26 11:32:06 | 000,534,261 | ---- | M] () (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\firefox\profiles\kp8852w0.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013.05.08 20:07:53 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\firefox\profiles\kp8852w0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2010.01.08 15:22:24 | 000,001,580 | ---- | M] () (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\firefox\profiles\kp8852w0.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\xpinstall\xpinstallConfirm.css
[2010.01.09 03:58:54 | 000,001,423 | ---- | M] () (No name found) -- C:\Users\xXBaseXx\AppData\Roaming\mozilla\firefox\profiles\kp8852w0.default\extensions\Strata40@SpewBoy.au\chrome\mozapps\xpinstall\xpinstallItemGeneric.png
[2013.05.22 21:11:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.05.22 21:11:32 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.11.06 13:40:16 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE File not found
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\xXBaseXx\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm File not found
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\xXBaseXx\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O8 - Extra context menu item: Free YouTube Download - C:\Users\xXBaseXx\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm File not found
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\xXBaseXx\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.4.1)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.4.1)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{61AE6971-47C3-47E4-8E0C-28539E7B6CF9}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{69B94DD0-3985-434A-8453-0D943E2FAA64}: NameServer = 62.109.123.196 213.191.74.18
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8BED4635-8D6C-46D0-AB8E-BD1538073031}: NameServer = 8.26.56.26,156.154.70.22
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9488151c-1e2d-11df-8422-002421eecdd5}\Shell - "" = AutoRun
O33 - MountPoints2\{9488151c-1e2d-11df-8422-002421eecdd5}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{9488151c-1e2d-11df-8422-002421eecdd5}\Shell\setup\command - "" = F:\setup.exe
O33 - MountPoints2\{ba2b95b6-f317-11df-83a7-a2ffbd12294c}\Shell - "" = AutoRun
O33 - MountPoints2\{ba2b95b6-f317-11df-83a7-a2ffbd12294c}\Shell\AutoRun\command - "" = H:\setup.exe
O33 - MountPoints2\{fffd9228-f59d-11de-9ed3-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fffd9228-f59d-11de-9ed3-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013.06.18 15:23:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013.06.18 15:20:42 | 002,347,384 | ---- | C] (ESET) -- C:\Users\xXBaseXx\Desktop\esetsmartinstaller_enu.exe
[2013.06.18 12:26:02 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\Documents\RIFT
[2013.06.18 12:16:29 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\AppData\Roaming\RIFT
[2013.06.18 12:16:29 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RIFT
[2013.06.18 12:16:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RIFT
[2013.06.18 08:53:18 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\Desktop\JRT
[2013.06.18 08:52:09 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\xXBaseXx\Desktop\JRT.exe
[2013.06.18 08:27:47 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\Desktop\temp
[2013.06.18 08:27:47 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\Desktop\erunt
[2013.06.18 08:23:01 | 000,000,000 | ---D | C] -- C:\JRT
[2013.06.17 22:15:11 | 000,000,000 | ---D | C] -- C:\FRST
[2013.06.17 22:14:48 | 001,926,844 | ---- | C] (Farbar) -- C:\Users\xXBaseXx\Desktop\FRST64.exe
[2013.06.17 22:13:57 | 001,365,333 | ---- | C] (Farbar) -- C:\Users\xXBaseXx\Desktop\FRST.exe
[2013.06.17 17:45:28 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\Desktop\Neuer Ordner (5)
[2013.06.17 17:43:01 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\xXBaseXx\Desktop\OTL.exe
[2013.06.05 20:58:28 | 000,000,000 | R--D | C] -- C:\Users\xXBaseXx\Dropbox
[2013.06.05 20:57:22 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013.06.05 20:54:56 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\AppData\Roaming\Dropbox
[2013.05.28 19:32:33 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\Documents\CPY_SAVES
[2013.05.27 16:23:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2013.05.25 13:40:53 | 000,000,000 | ---D | C] -- C:\Users\xXBaseXx\AppData\Roaming\FileZilla
[2013.05.25 13:40:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2013.05.25 13:40:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2013.05.25 12:17:39 | 008,043,008 | ---- | C] (Dxtory Software) -- C:\Windows\SysNative\DxtoryCodec.dll
[2013.05.22 21:08:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.05.22 00:19:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013.05.21 19:21:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Steam
[2013.05.21 18:47:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Resident Evil 6
[2013.05.21 01:32:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Metro Last Light
[9 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013.06.18 22:55:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.06.18 16:11:27 | 001,447,763 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\1371563650252.gif
[2013.06.18 15:58:57 | 000,765,413 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\1371561552323.gif
[2013.06.18 15:21:27 | 000,890,839 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\SecurityCheck.exe
[2013.06.18 15:20:44 | 002,347,384 | ---- | M] (ESET) -- C:\Users\xXBaseXx\Desktop\esetsmartinstaller_enu.exe
[2013.06.18 12:16:30 | 000,000,908 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\RIFT.lnk
[2013.06.18 10:51:05 | 000,017,168 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.06.18 10:51:05 | 000,017,168 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.06.18 10:45:58 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2013.06.18 10:45:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.06.18 10:45:45 | 2140,495,871 | -HS- | M] () -- C:\hiberfil.sys
[2013.06.18 08:52:10 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\xXBaseXx\Desktop\JRT.exe
[2013.06.18 08:17:37 | 000,648,201 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\adwcleaner2303.exe
[2013.06.17 22:14:59 | 001,926,844 | ---- | M] (Farbar) -- C:\Users\xXBaseXx\Desktop\FRST64.exe
[2013.06.17 22:14:04 | 001,365,333 | ---- | M] (Farbar) -- C:\Users\xXBaseXx\Desktop\FRST.exe
[2013.06.17 21:56:22 | 000,057,854 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\Logs.rar
[2013.06.17 17:45:17 | 000,000,000 | ---- | M] () -- C:\Users\xXBaseXx\defogger_reenable
[2013.06.17 17:44:34 | 000,377,856 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\gmer_2.1.19163.exe
[2013.06.17 17:43:01 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xXBaseXx\Desktop\OTL.exe
[2013.06.17 17:41:22 | 000,050,477 | ---- | M] () -- C:\Users\xXBaseXx\Desktop\Defogger.exe
[2013.06.14 03:04:41 | 001,622,922 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.06.14 03:04:41 | 000,709,210 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.06.14 03:04:41 | 000,661,492 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.06.14 03:04:41 | 000,153,562 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.06.14 03:04:41 | 000,125,682 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.06.14 03:04:33 | 001,622,922 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.06.14 00:24:05 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[9 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.06.18 16:11:27 | 001,447,763 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\1371563650252.gif
[2013.06.18 15:58:57 | 000,765,413 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\1371561552323.gif
[2013.06.18 15:21:21 | 000,890,839 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\SecurityCheck.exe
[2013.06.18 12:16:30 | 000,000,908 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\RIFT.lnk
[2013.06.18 08:17:37 | 000,648,201 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\adwcleaner2303.exe
[2013.06.17 21:56:22 | 000,057,854 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\Logs.rar
[2013.06.17 17:45:17 | 000,000,000 | ---- | C] () -- C:\Users\xXBaseXx\defogger_reenable
[2013.06.17 17:44:34 | 000,377,856 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\gmer_2.1.19163.exe
[2013.06.17 17:41:22 | 000,050,477 | ---- | C] () -- C:\Users\xXBaseXx\Desktop\Defogger.exe
[2013.05.21 01:48:26 | 000,000,856 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metro Last Light.lnk
[2013.04.01 01:45:13 | 000,291,088 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013.04.01 01:44:47 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013.03.27 21:11:29 | 000,015,522 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Roaming\PStrip.bk!
[2013.03.27 21:11:19 | 000,001,886 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Roaming\PStrip.bko
[2013.03.11 18:40:25 | 000,015,739 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Roaming\PStrip.bak
[2013.03.11 18:33:36 | 000,015,741 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Roaming\PStrip.ini
[2013.02.26 20:25:22 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.02.26 20:25:22 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.01.18 21:43:53 | 000,037,999 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2012.11.27 01:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.11.19 22:00:00 | 003,123,272 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012.10.07 00:18:46 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2012.10.06 16:02:55 | 000,877,747 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Local\Tempmusic.ogg
[2012.09.15 11:31:48 | 000,000,061 | ---- | C] () -- C:\Windows\sbwin.ini
[2012.09.14 21:57:17 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012.04.23 17:06:34 | 000,006,817 | ---- | C] () -- C:\Windows\DiabUnin.dat
[2012.01.27 16:11:03 | 000,168,864 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe
[2011.12.21 17:54:55 | 000,000,620 | ---- | C] () -- C:\Windows\eReg.dat
[2011.09.28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011.09.19 15:03:40 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll
[2011.09.13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.07.19 23:52:56 | 000,005,002 | ---- | C] () -- C:\ProgramData\kaevcwgh.slj
[2011.07.19 23:40:37 | 000,005,117 | ---- | C] () -- C:\ProgramData\hvcatrnw.tht
[2011.01.25 16:45:47 | 000,001,852 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Roaming\ImperatorProfile0.dat
[2010.04.12 21:20:19 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini
[2010.02.20 22:12:15 | 000,000,096 | ---- | C] () -- C:\Users\xXBaseXx\AppData\Local\fusioncache.dat
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011.06.29 19:38:06 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\.minecraft
[2012.05.06 20:46:49 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Alarmstufe Rot 3 Der Aufstand
[2010.03.28 14:13:14 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Bioshock2
[2010.08.12 21:47:10 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Blender Foundation
[2010.08.12 21:49:41 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\CB Model Pro
[2010.12.29 00:52:50 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Command & Conquer 3 Kanes Rache
[2010.12.24 19:29:43 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2010.02.03 20:22:17 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Command and Conquer 4 Beta
[2013.06.17 17:02:44 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Dropbox
[2013.05.12 15:10:30 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\DVDVideoSoft
[2013.05.26 18:22:42 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\FileZilla
[2011.10.30 13:56:34 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Firefly Studios
[2011.11.29 12:21:02 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\fltk.org
[2012.03.12 09:30:17 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Foxit Software
[2010.12.25 22:30:14 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\FreeVideoConverter
[2011.02.04 23:28:15 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\GetRightToGo
[2010.08.13 19:26:40 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Leadertech
[2010.09.09 22:36:19 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\LolClient
[2012.05.24 11:16:58 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\LolClient2
[2011.11.22 21:40:13 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\MAXON
[2013.03.05 23:50:00 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Might & Magic Heroes VI
[2011.07.19 23:41:02 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\MOVAVI
[2010.01.11 21:13:01 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Mumble
[2012.01.15 20:54:10 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\NationRed
[2013.03.02 13:09:24 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Natural Selection 2
[2010.09.09 11:58:26 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Need for Speed World
[2011.03.11 16:57:19 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\nHancer
[2010.11.01 07:52:46 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\OpenOffice.org
[2012.01.22 19:21:36 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Opera
[2012.12.29 17:07:50 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Origin
[2013.03.08 08:58:46 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Rainmeter
[2010.05.03 21:32:13 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Red Alert 3
[2013.06.18 12:34:19 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\RIFT
[2012.04.13 07:58:02 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\RotMG.Production
[2010.05.21 23:48:38 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Sports Interactive
[2012.12.04 19:36:38 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\TeamViewer
[2012.07.25 23:36:55 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Teeworlds
[2012.11.24 20:21:25 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Theta
[2013.06.18 23:19:14 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\TS3Client
[2012.11.06 00:50:36 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\Ubisoft
[2012.09.30 12:52:39 | 000,000,000 | ---D | M] -- C:\Users\xXBaseXx\AppData\Roaming\wargaming.net
========== Purity Check ==========
< End of report > Mit einem Security Check log kann ich dir erneut nicht dienen.
Irgendwie scheint der Rechner Programme nicht zu mögen, die mit dem DOS-Fenster arbeiten. Er kennt angeblich die ganzen Befehle nicht, die das Prog. in die DOS-Box eingibt...
Wie dem auch sei, die Umleitung auf die Scam page findet nicht mehr statt und der PC stürzt auch nicht mehr ab. Sieht soweit gut aus.
Bis zu diesem Punkt muss ich dir schon mal vielmals danken. Ohne dich hätte ich das System
wohl doch platt gemacht. |